GI LogoGI Logo
  • Anmelden
Digitale Bibliothek
    • Gesamter Bestand

      • Bereiche & Sammlungen
      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
    • Diese Sammlung

      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
Digital Bibliothek der Gesellschaft für Informatik e.V.
GI-DL
    • English
    • Deutsch
  • Deutsch 
    • English
    • Deutsch
Dokumentanzeige 
  •   Startseite
  • Lecture Notes in Informatics
  • Proceedings
  • Sicherheit
  • P228 - Sicherheit 2014 - Sicherheit, Schutz und Zuverlässigkeit
  • Dokumentanzeige
JavaScript is disabled for your browser. Some features of this site may not work without it.
  •   Startseite
  • Lecture Notes in Informatics
  • Proceedings
  • Sicherheit
  • P228 - Sicherheit 2014 - Sicherheit, Schutz und Zuverlässigkeit
  • Dokumentanzeige

Forensic zero-knowledge event reconstruction on filesystem metadata

Autor(en):
Kälber, Sven [DBLP] ;
Dewald, Andreas [DBLP] ;
Idler, Steffen [DBLP]
Zusammenfassung
Criminal investigations today can hardly be imagined without the forensic analysis of digital devices, regardless of whether it is a desktop computer, a mobile phone, or a navigation system. This not only holds true for cases of cybercrime, but also for traditional delicts such as murder or blackmail, and also private corporate investigations rely on digital forensics. This leads to an increasing number of cases with an ever-growing amount of data, that exceeds the capacity of the forensic experts. To support investigators to work more efficiently, we introduce a novel approach to automatically reconstruct events that previously occurred on the examined system and to provide a quick overview to the investigator as a starting point for further investigation. In contrast to the few existing approaches, our solution does not rely on any previously profiled system behavior or knowledge about specific applications, log files, or file formats. We further present a prototype implementation of our so-called zero knowledge event reconstruction approach, that solely tries to make sense of characteristic structures in file system metadata such as fileand folder-names and timestamps.
  • Vollständige Referenz
  • BibTeX
Kälber, S., Dewald, A. & Idler, S., (2014). Forensic zero-knowledge event reconstruction on filesystem metadata. In: Katzenbeisser, S., Lotz, V. & Weippl, E. (Hrsg.), Sicherheit 2014 – Sicherheit, Schutz und Zuverlässigkeit. Bonn: Gesellschaft für Informatik e.V.. (S. 331-343).
@inproceedings{mci/Kälber2014,
author = {Kälber, Sven AND Dewald, Andreas AND Idler, Steffen},
title = {Forensic zero-knowledge event reconstruction on filesystem metadata},
booktitle = {Sicherheit 2014 – Sicherheit, Schutz und Zuverlässigkeit},
year = {2014},
editor = {Katzenbeisser, Stefan AND Lotz, Volkmar AND Weippl, Edgar} ,
pages = { 331-343 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
DateienGroesseFormatAnzeige
331.pdf232.8Kb PDF Öffnen

Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken

Mehr Information

ISBN: 978-3-88579-622-0
ISSN: 1617-5468
Datum: 2014
Sprache: en (en)
Typ: Text/Conference Paper
Sammlungen
  • P228 - Sicherheit 2014 - Sicherheit, Schutz und Zuverlässigkeit [38]

Zur Langanzeige


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.

 

 


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.